GUIDE · PERMISSIONS

Configure Codex model, reasoning and access permissions

Model choice and file access are separate controls. The account owner can select a compatible model and reasoning level, then decide whether the task is read-only, may write to the workspace or may use full access.

Start with read-only execution

Read-only access is the safest default for exploring a repository, reviewing tests or asking for a plan. It lets Codex inspect the project without changing files.

Authorize workspace writes or full access

Workspace-write access permits changes inside the configured project. Full access is an explicit account-level choice and should be enabled only when the owner accepts the broader operating scope.

Handle approval requests

When an operation needs confirmation, the pending request is surfaced in the task conversation and reminded periodically. Approve or decline it from the authorized owner account; do not treat a waiting state as a failed task.

TRY THE WORKFLOW

Connect your first VM

Start with 2,000 messages and test the workflow from your own environment.